Skip to content

App Attest​

Apple App Attest for the FundlyHub iOS app. A request carrying a valid assertion may skip reCAPTCHA on POST /payments/create-intent and POST /donations, guest or signed in. See the Native Clients guide for the byte-level protocol.


Issue an App Attest challenge​

POST
/app-attest/challenge

A random, single-use challenge for the iOS app, valid for
expires_in_seconds (300). Fetch one before attesting a key and one
before every donation request that carries an App Attest assertion.

Public (guests call it). Rate limited to 30 a minute per address.
Answers 503 with code: APP_ATTEST_DISABLED while App Attest is not
configured on the server.

Responses​

A fresh challenge (Cache-Control: no-store).

application/json
JSON
{
"challenge": "q7uE3fP9yK2sV1xW4zA6bC8dE0fG2hJ4kL6mN8pR0tU",
"expires_in_seconds": 300
}

Playground​

Samples​


Register an App Attest key​

POST
/app-attest/attest

Register a device key with its attestation. The server verifies the
certificate chain to Apple's App Attestation Root CA, that the
attestation was made for challenge
(clientDataHash = SHA256(UTF-8 bytes of challenge)), the App ID, the
environment, a zero counter and that key_id is the key's hash, then
stores the public key. Attest once per key; attesting a key that is
already registered changes nothing.

Public (guests call it). Rate limited to 10 a minute per address.

Request Body​

application/json
JSON
{
"key_id": "string",
"attestation": "string",
"challenge": "string"
}

Responses​

Key verified and registered.

Playground​

Server
Body

Samples​


Powered by VitePress OpenAPI

Built with VitePress